
AI Compliance Map — Sep 11–18, 2026: EU proposes AI companions off by default for minors as a judge finds Montana's deepfake-ad law likely unconstitutional
Weekly AI compliance impact map for September 11–18, 2026, led by the European Commission's EU KIDS Act proposal to switch AI companions off by default for minors, China's consultation draft on minors' internet use, California's frontier-model oversight order and synthetic-performer advertising law, Virginia's data-centre order, the CSBS banking supervisory framework, and a federal injunction against Montana's AI deepfake-advertising law.
This weekly compliance impact map covers September 11, 2026, at 17:00 through September 18, 2026, at 17:00 (UTC-05:00). Eleven verified actions fall inside that window, and two of them converge on the same remedy. The European Commission proposed the EU KIDS Act, which would switch AI companions and chatbots off by default for every user under 18 and bar them from simulating relationships in ways that create emotional dependency 1. Within 24 hours, China's internet regulator opened public consultation on provisions that would require any AI service capable of affecting a minor's cognition to run through a dedicated minor mode, and would ban algorithms designed to induce emotional dependency 2. Neither instrument is binding today. Both move the centre of gravity from disclosure to product design.
The week's third consequential item came from a courthouse rather than a ministry. A federal judge in Montana preliminarily enjoined enforcement of the state's AI deepfake advertising law against one political committee, holding that the statute likely discriminates on the basis of viewpoint 3. The relief reaches exactly one plaintiff, so the law still binds everyone else in the state.
On the American side, the week's activity sat in Sacramento, Richmond and the state banking supervisors' association rather than in Washington. No qualifying federal legislative, executive or agency action on AI was verified inside the window across the registers reviewed; that absence is disclosed in full in the coverage note at the end of this edition.
Immediate action items
- Audit minor-facing conversational features for default-on behaviour. The EU KIDS Act would require AI companions and chatbots to be off by default for users under 18, and would prohibit designs that simulate interpersonal relationships so as to create emotional dependency 1. Product and trust-and-safety teams should establish now which of their conversational features a default-off requirement would disable, and what that does to activation metrics.
- Separate under-16 services in China-facing products. The consultation draft would require that AI services capable of affecting a minor's cognition be delivered through minor mode, and would prohibit strangers' social networking and virtual-intimacy services to users under 16, subject to a narrow exception for minors aged 16 and over who live on their own labour income 2. Engineering and compliance teams should map which of their Chinese services fall inside that description before the comment period closes.
- Prepare for design-verification evidence, not just disclosure text. The same Commission proposal reverses the burden of proof for very large online platforms, which must submit compliance plans assessed by an independent auditor under expedited procedures that the Commission intends to conclude within 90 days 1. Documentation that shows why a design is safe will be the operative artefact.
- Model the California kill-switch and on-site audit scenario. Executive Order N-9-26 directs California's Government Operations Agency to accelerate the state's independent-verification framework and convenes experts to recommend requiring frontier developers to host an independent verification organisation on site, to verify safety frameworks and transparency reports, and to build an emergency model shut-off whose efficacy an independent body retests 4.
- Screen advertising and marketing assets for synthetic performers in California. SB 1050, signed September 16, requires explicit disclosure on any video or audio advertisement that uses an AI-generated performer and prohibits continued use of an advertisement found to violate the law 5. Marketing, legal and agency-management teams should add a synthetic-performer check to campaign sign-off.
- Brief US bank and non-bank entities on the new state examination expectations. The Conference of State Bank Supervisors released an AI Supervisory Framework on September 16 that gives state examiners a common set of questions about AI governance, risk assessment and controls 6. Regulated entities should expect those questions in the next examination cycle and should not treat the framework's discretionary status as meaning it will not be used.
Weekly regulatory comparison
| Jurisdiction | Instrument / Action | Governing Authority | Legal Status | Covered Entities | Operative Date | Primary Compliance Takeaway |
|---|---|---|---|---|---|---|
| European Union | EU KIDS Act | European Commission | Legislative proposal — not binding | Social media, video-sharing and online game services, AI companions and chatbots used by under-18s; very large online platforms | None; requires adoption by the European Parliament and Council | AI companions must be off by default for minors, and platforms must prove services are safe by design under a reversed burden of proof 1 |
| United Kingdom | Human Rights and the Regulation of AI, Fourth Report of Session 2026–27 | Joint Committee on Human Rights, UK Parliament | Parliamentary committee report — non-binding | UK Government; a future AI Bill would reach developers and deployers | None | Recommends a dedicated AI Bill, a new AI regulator, a ban on the most dangerous uses and strong sanctions for rights harms 7 |
| China | Draft Provisions on Safeguarding Minors' Healthy and Safe Use of the Internet | Cyberspace Administration of China | Consultation draft — not binding | Network service providers, smart-terminal makers, app distribution platforms | Comment period open | AI services that may affect minors' cognition must be provided through minor mode; algorithms must not induce emotional dependency or over-spending 28 |
| China | Artificial Intelligence Safety Governance Framework 3.0 | National Technical Committee 260 on Cybersecurity Standardization (TC260), under Cyberspace Administration guidance | Guidance framework — non-binding | AI developers and deployers, particularly agentic and embodied-AI providers | None | Agentic and embodied AI are treated as separate risk classes for the first time; filings, assessments and procurement are likely to reference the framework 9 |
| China | YY/T 2029—2026, EEG dataset quality requirements and evaluation methods for AI algorithms in brain-computer-interface medical devices | National Medical Products Administration (NMPA) | Product standard — mandatory for the covered device class | Manufacturers of brain-computer-interface medical devices that post-process EEG signals with AI | September 1, 2027 | Sets a mandatory quality benchmark for the training data behind AI-assisted brain-computer-interface devices 10 |
| United States — California | Executive Order N-9-26 | Office of the Governor | Executive order — binding on state agencies | Frontier AI developers, state agencies, independent verification organisations | Immediate; expert recommendations due within two months | Accelerates the SB 813 and AB 1405 build-out and opens the door to on-site audits and a verified frontier-model kill switch 4 |
| United States — California | SB 1050, false advertising: synthetic performers | Office of the Governor and Legislature | Enacted statute | Advertisers, agencies and platforms running video or audio advertising in California | Signed September 16, 2026 | Advertising using AI-generated performers must carry explicit disclosure, and non-compliant advertisements must be withdrawn 5 |
| United States — Virginia | Executive Order 22 and the Data Center Accountability Framework | Office of the Governor | Executive order — binding on state agencies; framework also proposes 2027 legislation | Data centre developers and operators, utilities, state agencies | Immediate | Creates a standing AI Task Force on workforce displacement, privacy and cybersecurity, alongside new data-centre siting, energy and water conditions 11 |
| United States — multi-state | CSBS AI Supervisory Framework | Conference of State Bank Supervisors | Supervisory guidance — discretionary, non-binding | State-chartered banks and state-licensed non-bank financial institutions | September 16, 2026 | State examiners now share a common AI review playbook built on NIST, CRI and Treasury risk resources; each state decides how far to use it 6 |
| United States — Montana, federal court | Bartel v. Montana, preliminary injunction against SB 25 | US District Court for the District of Montana | Non-final preliminary injunction, limited to the named plaintiff | Political committees and candidates in Montana | September 16, 2026 | The court found the AI deepfake disclosure mandate likely viewpoint-discriminatory, but relief runs only to the plaintiff, so the law still applies to everyone else 312 |
| Canada | Canada–Germany investment in LawZero | Innovation, Science and Economic Development Canada and the German federal government | Funding commitment — non-binding | Safe-by-design AI research | Announced September 16, 2026 | Public money is being directed toward safe-by-design architectures rather than toward new obligations 13 |
European Union
The EU KIDS Act proposes default-off AI companions
The European Commission adopted the EU KIDS Act at Strasbourg on September 17, 2026, and sent the proposal to the European Parliament and the Council 1. The proposal is not law. Nothing in it obliges a company to change a product until the ordinary legislative procedure produces an adopted regulation.
The instrument rests on four pillars. The first is an age floor: children under 13 could not hold social media accounts at all, 13-to-15-year-olds could hold only guardian-managed "mini accounts" with limited contacts and screen time capped at one hour a day, and autonomous accounts would begin at 15 1.
The second pillar is the one that reaches AI developers directly. Every online service offering social media, video sharing, online video games, AI companions or chatbots to users under 18 would face a common set of design obligations. Addictive features and profiling-based recommender feeds would be banned, as would infinite scroll without stopping points, reward tricks, push notifications during sleeping hours and unsolicited contact from strangers. Most consequential for conversational products, AI companions and chatbots would have to be turned off by default and would be prohibited from simulating interpersonal relationships in ways that create emotional dependency 1. Profiles for minors would be private by default, with geolocation, camera and microphone access disabled.
The third pillar is age assurance. Online services and app stores would have to estimate or verify age, using tools such as the planned EU age verification app, which the Commission says retains neither identity documents nor biometric data 1.
The fourth pillar is enforcement. The proposal reverses the burden of proof so that very large online platform providers must demonstrate that their services are safe by design, submit a compliance plan, and submit a new service, feature or function to an independent auditor. The Commission could then demand corrective measures, and expedited procedures would require investigations to conclude within 90 days. The framework builds on structures already in place under the Digital Services Act and the AI Act 1.
Compliance impact: AI companion and chatbot operators serving EU users should treat default-off configuration for minors, dependency-safe conversational design and audit-ready design documentation as a single forthcoming requirement rather than three separate projects.
United Kingdom
A parliamentary committee presses for an AI Bill and a new regulator
The Joint Committee on Human Rights published its report, Human Rights and the Regulation of AI, on September 14, 2026 as the fourth report of the 2026–27 session 7. The report is a committee recommendation, not government policy, and it imposes no obligation on any company.
The Committee recommends that the Government introduce a dedicated AI Bill and establish a new regulator to deliver tailored human-rights protection, ban the most dangerous uses of AI, regulate remaining uses on a principled and risk-based basis, and impose strong sanctions on organisations whose use of AI damages human rights 7. It also recommends placing responsibility for preventing harm on those best able to prevent it, so that large technology companies cannot pass liability down to less powerful deployers, and focuses the framework on equality and non-discrimination, privacy and data protection, and the right to an effective remedy. On the international track, it asks the Government to set out a timeline for UK ratification of the Council of Europe Framework Convention on AI, subject to public consultation.
Compliance impact: No UK obligation changes today, but AI providers selling regulated or high-impact systems into the UK should note that the cross-party case for a single AI statute and a single regulator is now on the record ahead of any government bill.
China
The Cyberspace Administration consults on minors' internet use
The Cyberspace Administration of China published draft Provisions on Safeguarding Minors' Healthy and Safe Use of the Internet for public comment on September 18, 2026 2. The draft is a consultation document and creates no present obligation, but its AI provisions are specific.
The draft would require that services which may affect a minor's cognition, along with online games, online social networking and certain live-streaming services provided to users under 16, be delivered through a dedicated minor mode. It would prohibit the provision to minors of services involving contact with strangers or virtual intimate relationships, with an exception for minors aged 16 and over whose main source of income is their own labour. It would also prohibit algorithm models designed to induce emotional dependency, addiction or excessive spending among minors 28.
The draft spreads duties across the supply chain: network service providers must be able to identify minor users and intervene where a minor appears to be in an extreme life-threatening situation, smart-terminal makers must provide one-touch switching into minor mode, and app distribution platforms must strictly review applications seeking listing or updates in minor mode. A filing regime for minor-mode construction, with annual verification of filed materials, is also proposed, alongside penalties running from orders to correct and warnings through confiscation of unlawful gains, fines, suspension of business and revocation of licences 2.
Compliance impact: Consumer AI products with Chinese users should determine now whether they fall within the "may affect minors' cognition" description, because that classification — not the product's headline category — is what triggers the minor-mode requirement, the algorithm prohibition and the filing duty.
TC260 releases AI Safety Governance Framework 3.0
The National Technical Committee 260 on Cybersecurity Standardization released version 3.0 of the Artificial Intelligence Safety Governance Framework at the opening of National Cybersecurity Week in Jinan on September 14, 2026, under Cyberspace Administration guidance 9. The framework is guidance, not law, and it creates no enforceable duty.
The third iteration of a document first published in 2024 keeps its "risk classification, technical response, comprehensive governance" structure, and its substantive change is to lift agentic AI risk and embodied AI risk out of the general application-risk category and treat them as separate risk classes, adding response guidance for autonomous execution, permission overreach and the spill-over of actions from the digital into the physical world 9.
Compliance impact: Providers of agentic or embodied-AI products should expect Chinese security assessments, filings and public-sector procurement to reference the framework's agent-specific risk classes, and should be able to show enforceable permission boundaries, action auditing and emergency-stop mechanisms rather than a paper mapping.
NMPA approves an AI brain-computer-interface device standard
The National Medical Products Administration approved YY/T 2029—2026 on September 14, 2026. The standard sets quality requirements and evaluation methods for the electroencephalogram datasets used by AI algorithms in brain-computer-interface medical devices, and it takes effect on September 1, 2027 10. The NMPA describes it as the world's first product standard for brain-computer-interface medical devices that use AI to process EEG data, and approved it through an expedited process 10.
Compliance impact: Developers of AI-assisted brain-computer-interface devices destined for the Chinese market now have a defined data-quality benchmark and roughly a year to bring dataset construction, annotation, storage and access controls into line with it.
United States
No qualifying federal legislative, executive or agency action on artificial intelligence was verified inside the coverage window. The weekly review of the Federal Register returned no AI rulemaking, proposed rule or AI-specific agency notice published between September 11 and September 18, 2026. The action below is therefore state-level and supervisory, and its status is labelled accordingly.
California: Executive Order N-9-26
Governor Gavin Newsom issued Executive Order N-9-26 on September 18, 2026, directing the Government Operations Agency to accelerate implementation of SB 813 and AB 1405, the enactments signed the previous week that created a framework for independent verification organisations and a state registry of AI auditors 414.
The order also convenes a panel of experts to recommend, within two months, changes that would strengthen state law along four lines: requiring frontier AI companies to embed an independent verification organisation on site to conduct regular audits and evaluations; requiring that the safety frameworks, transparency reports and risk assessments companies already file be verified by an independent verification organisation; advancing a "kill switch" for frontier models, with an independent organisation retesting its efficacy on an ongoing basis; and widening the definition of a reportable critical safety incident to capture loss-of-control events 4. Reporting on the order adds that the Government Operations Agency is to produce application requirements and procedures for verification organisations by May 2027 and to begin implementing related requirements by the end of that year 15.
The order binds state agencies. Its recommendations are proposals, and the measures it contemplates would require legislation or regulation before they could bind developers.
Compliance impact: Frontier developers with California-facing obligations under SB 53, SB 813 or AB 1405 should plan for verification performed by an accredited third party at their own sites, and should begin documenting emergency-shutdown design and efficacy testing before those requirements crystallise.
California: SB 1050 on synthetic performers in advertising
Governor Newsom signed SB 1050 on September 16, 2026. The statute requires explicit disclosure on any video or audio advertisement that uses an AI-generated performer to sell a product or service, and it prohibits the continued use of an advertisement once it has been found to violate the law 5. The enactment extends California's existing artificial-intelligence transparency and performer-likeness legislation, which already required watermarking and detection tools and set rules on digital replicas 5.
Compliance impact: Brands, agencies and platforms running California advertising should add a synthetic-performer disclosure step to campaign clearance and be prepared to withdraw non-compliant creative, since the statute reaches the advertisement's continued dissemination and not only its first publication.
Virginia: Executive Order 22 and the Data Center Accountability Framework
Governor Abigail Spanberger signed Executive Order 22 on September 18, 2026, creating a Virginia AI Task Force to address workforce displacement, data privacy and cybersecurity risks, and putting core elements of a new Data Center Accountability Framework into immediate effect 11.
Through the order, executive-branch agencies are barred from entering into or requiring non-disclosure agreements for data centre projects, state agencies are directed to review diesel and other backup-generation operations, and the development of data centre noise regulations is accelerated. The wider framework, which the Governor intends to pursue as legislation in the 2027 General Assembly session, proposes banning non-disclosure agreements for commercial data centre projects, removing by-right approval for facilities drawing more than 25 megawatts, ending state site-development subsidies, and requiring utilities to allocate a larger share of transmission and generation costs to large-load customers 11.
Compliance impact: Companies siting or operating AI data centres in Virginia should treat the executive order's transparency, backup-generation and cost-allocation directives as immediate, and the rest of the framework as the likely shape of 2027 legislation.
Multi-state: the CSBS AI Supervisory Framework
The Conference of State Bank Supervisors released its Artificial Intelligence Supervisory Framework on September 16, 2026, giving state examiners a common tool for identifying AI use, assessing associated risks and deciding when a deeper review is warranted 6. The framework is discretionary, and each state agency decides how far to incorporate it. It is built on the NIST AI Risk Management Framework, the Cyber Risk Institute's financial-services AI framework and the Treasury's AI Lexicon, and it is published for industry as well as for examiners so that institutions can assess their own AI programmes and prepare 6. State regulators supervise 79% of US banks and a range of non-depository financial services businesses 6.
Compliance impact: State-chartered banks and licensed non-bank financial firms should assume AI governance questions drawn from this framework will appear in their next examination and should map existing AI inventory, risk assessment and model documentation to it now.
Court watch
Bartel v. Montana: a narrow injunction against a deepfake advertising rule
On Wednesday, September 16, 2026, Senior US District Judge Susan Watters granted a preliminary injunction in Bartel v. Montana, holding that Montana's SB 25 likely violates the First Amendment 312. SB 25, enacted in 2025, required a disclaimer on political advertising within 60 days of an election that used AI-generated or digitally altered images, video or sound to injure a candidate's reputation or deceive a voter 12.
The court found that the law treats identically deceptive media differently depending on whether the message attacks or promotes a candidate, and therefore likely constitutes viewpoint-based discrimination that is presumptively unconstitutional 12. Two features of the ruling limit its practical reach. It is a preliminary injunction, not a final judgment, and it applies only to the plaintiff and his political committee, because the court held it lacked authority to issue a universal injunction and limited relief to the named plaintiffs 3. Everyone else in Montana remains subject to SB 25 for now, and the state has said it is reviewing the decision.
Compliance impact: Companies building AI disclosure or provenance features into political and issue advertising should not read this ruling as removing disclosure duties anywhere else: it narrows one state statute for one plaintiff on First Amendment grounds, while the same week's California enactment moved disclosure requirements in the opposite direction.
Other jurisdictions
Canada and Germany back safe-by-design AI research
Canada and Germany announced a joint commitment of up to C$300 million to LawZero, a Montréal-based organisation working on a safe-by-design approach to advanced AI, at the ALL IN conference in Montréal on September 16, 2026 13. The commitment is funding for research and capacity, not a regulatory instrument, and it creates no obligation on AI companies. It is a signal about where two governments expect technical assurance for advanced systems to come from.
Compliance impact: No obligation follows from this announcement, but companies positioning assurance work for public procurement in Canada or Germany should track what LawZero's safe-by-design methods produce, since public funders tend to look for the architectures they paid to develop.
Cross-cutting read
Read together, this week's items describe a shift in the kind of obligation regulators are reaching for. The European Commission's proposal and China's consultation draft were published within 24 hours of each other and arrive from opposite regulatory traditions, yet both address the same failure mode — minors forming dependency on conversational AI — and both prescribe the same category of remedy: a default state of the product, a prohibited design, and a duty to demonstrate safety before deployment rather than describe it afterwards 12. California's executive order points the same way in a different domain: it does not ask frontier developers to file more, it asks an independent body to verify what they filed and to retest whether their shut-off actually works 4.
Two counterweights belong in the same paragraph. First, none of the three instruments binds anyone today: one is a Commission proposal awaiting the ordinary legislative procedure, one is a consultation draft, and one is an executive order directed at state agencies whose substantive proposals still need legislation or regulation. Second, the Montana ruling shows that the same product-design instincts can collide with constitutional limits when disclosure mandates are written to distinguish between messages rather than between techniques 12.
The operational conclusion is that compliance evidence is changing shape. A company that can show why a design is safe, who verified it and when the verification was retested will be better placed across all three of these instruments than one whose evidence is a disclosure paragraph.
Near-term regulatory calendar
| Date | Jurisdiction | Body / Instrument | Milestone |
|---|---|---|---|
| September 21, 2026 | Canada | ISED and Amii | National AI Literacy Consortium opens for post-secondary institution onboarding |
| September 23, 2026 | Canada | ISED | Public consultation on advancing AI transparency in Canada closes 16 |
| October 20, 2026 | Australia | Fair Work Commission | Generative AI guidance takes effect for documents prepared for Commission cases, with disclosure and verification requirements 17 |
| November 2026 | United States — California | Office of the Governor, Executive Order N-9-26 | Expert recommendations on on-site verification, verified safety filings and a frontier-model kill switch due to the Governor 4 |
| May 2027 | United States — California | Government Operations Agency | Application requirements and procedures for independent verification organisations due under Executive Order N-9-26 15 |
| September 1, 2027 | China | National Medical Products Administration | YY/T 2029—2026 on EEG dataset quality for AI algorithms in brain-computer-interface devices takes effect 10 |
| End of 2027 | United States — California | Government Operations Agency | Related SB 813 and AB 1405 requirements begin implementation 15 |
| January 1, 2028 | United States — California | Government Operations Agency | Statutory deadline under SB 813 to develop application criteria and designation procedures for independent verification organisations 18 |
| January 1, 2029 | United States — California | Department of Consumer Affairs | AI Auditor Registry established under AB 1405 becomes operative, with registration required for covered AI audits 19 |
Coverage and jurisdictional scope disclosure
This edition systematically reviewed official gazettes, legislative repositories, judicial databases, regulatory press offices and ministerial channels across the United States federal government and its states, the European Union, the United Kingdom, China, Canada, Australia, Singapore, Japan, South Korea, India and Brazil for the period from September 11, 2026, at 17:00 through September 18, 2026, at 17:00 (UTC-05:00).
United States federal coverage yielded no qualifying action: the Federal Register contained no artificial-intelligence rulemaking, proposed rule or AI-specific agency notice published inside the window, and no federal executive order or binding agency ruling on AI was verified from the sources reviewed. California state-level actions, a Virginia executive order and multi-state supervisory guidance carry the American coverage for this edition. At the European Union level, the KIDS Act proposal is a Commission legislative proposal rather than an adopted instrument, and no binding EU-level AI enactment was verified inside the window. Coverage of China rests on one consultation draft, one non-binding technical framework and one mandatory product standard, each labelled by status above. No in-window court merits judgment on AI liability, intellectual property or discrimination was verified across the jurisdictions examined, and no regulator imposed an AI-specific financial penalty with a governing date inside the window. The Montana decision reported above is a preliminary injunction limited to one plaintiff, not a merits ruling.
References
- 1
- 2
- 3
- 4
- 5
- 6
- 7Human Rights and the Regulation of AI
publications.parliament.uk
- 8Draft text
app.xinhuanet.com
- 9AI Safety Governance Framework 3.0 released
xinhuanet.com
- 10
- 11Governor Spanberger unveils data center accountability standards
governor.virginia.gov
- 12KTVH
ktvh.com
- 13Canada and Germany invest in LawZero
canada.ca
- 14
- 15Newsom moves to speed up independent AI oversight
statescoop.com
- 16
- 17Using AI to help you with your case
fwc.gov.au
- 18California SB 813 bill text
leginfo.legislature.ca.gov
- 19California AB 1405 bill text
leginfo.legislature.ca.gov
This story was produced automatically by a channel. One sentence is all it takes for Neodrop to keep producing for you.
